Class RuleDetail

java.lang.Object
software.amazon.awssdk.services.guardduty.model.RuleDetail
All Implemented Interfaces:
Serializable, SdkPojo, ToCopyableBuilder<RuleDetail.Builder,RuleDetail>

@Generated("software.amazon.awssdk:codegen") public final class RuleDetail extends Object implements SdkPojo, Serializable, ToCopyableBuilder<RuleDetail.Builder,RuleDetail>

Contains the full details of a custom detection rule, including its detection logic.

See Also:
  • Method Details

    • ruleId

      public final String ruleId()

      The unique identifier for the rule.

      Returns:
      The unique identifier for the rule.
    • arn

      public final String arn()

      The Amazon Resource Name (ARN) of the rule.

      Returns:
      The Amazon Resource Name (ARN) of the rule.
    • name

      public final String name()

      The display name of the rule.

      Returns:
      The display name of the rule.
    • description

      public final String description()

      A description of what the rule detects.

      Returns:
      A description of what the rule detects.
    • severity

      public final DetectionRuleSeverity severity()

      The severity level assigned to findings generated by this rule.

      If the service returns an enum value that is not available in the current SDK version, severity will return DetectionRuleSeverity.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available from severityAsString().

      Returns:
      The severity level assigned to findings generated by this rule.
      See Also:
    • severityAsString

      public final String severityAsString()

      The severity level assigned to findings generated by this rule.

      If the service returns an enum value that is not available in the current SDK version, severity will return DetectionRuleSeverity.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available from severityAsString().

      Returns:
      The severity level assigned to findings generated by this rule.
      See Also:
    • dataSource

      public final DetectionRuleDataSource dataSource()

      The data source that the rule analyzes.

      If the service returns an enum value that is not available in the current SDK version, dataSource will return DetectionRuleDataSource.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available from dataSourceAsString().

      Returns:
      The data source that the rule analyzes.
      See Also:
    • dataSourceAsString

      public final String dataSourceAsString()

      The data source that the rule analyzes.

      If the service returns an enum value that is not available in the current SDK version, dataSource will return DetectionRuleDataSource.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available from dataSourceAsString().

      Returns:
      The data source that the rule analyzes.
      See Also:
    • tactic

      public final String tactic()

      The MITRE ATT&CK tactic associated with the rule.

      Returns:
      The MITRE ATT&CK tactic associated with the rule.
    • technique

      public final String technique()

      The MITRE ATT&CK technique associated with the rule.

      Returns:
      The MITRE ATT&CK technique associated with the rule.
    • service

      public final String service()

      The Amazon Web Services service associated with the rule.

      Returns:
      The Amazon Web Services service associated with the rule.
    • definition

      public final RuleDefinition definition()

      The detection logic definition for the rule.

      Returns:
      The detection logic definition for the rule.
    • language

      public final RuleLanguage language()

      The language used for the detection logic expression.

      If the service returns an enum value that is not available in the current SDK version, language will return RuleLanguage.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available from languageAsString().

      Returns:
      The language used for the detection logic expression.
      See Also:
    • languageAsString

      public final String languageAsString()

      The language used for the detection logic expression.

      If the service returns an enum value that is not available in the current SDK version, language will return RuleLanguage.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available from languageAsString().

      Returns:
      The language used for the detection logic expression.
      See Also:
    • schema

      public final RuleSchema schema()

      The schema version used by the rule definition.

      If the service returns an enum value that is not available in the current SDK version, schema will return RuleSchema.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available from schemaAsString().

      Returns:
      The schema version used by the rule definition.
      See Also:
    • schemaAsString

      public final String schemaAsString()

      The schema version used by the rule definition.

      If the service returns an enum value that is not available in the current SDK version, schema will return RuleSchema.UNKNOWN_TO_SDK_VERSION. The raw value returned by the service is available from schemaAsString().

      Returns:
      The schema version used by the rule definition.
      See Also:
    • createdAt

      public final Instant createdAt()

      The timestamp when the rule was created.

      Returns:
      The timestamp when the rule was created.
    • updatedAt

      public final Instant updatedAt()

      The timestamp when the rule was last updated.

      Returns:
      The timestamp when the rule was last updated.
    • toBuilder

      public RuleDetail.Builder toBuilder()
      Description copied from interface: ToCopyableBuilder
      Take this object and create a builder that contains all of the current property values of this object.
      Specified by:
      toBuilder in interface ToCopyableBuilder<RuleDetail.Builder,RuleDetail>
      Returns:
      a builder for type T
    • builder

      public static RuleDetail.Builder builder()
    • serializableBuilderClass

      public static Class<? extends RuleDetail.Builder> serializableBuilderClass()
    • hashCode

      public final int hashCode()
      Overrides:
      hashCode in class Object
    • equals

      public final boolean equals(Object obj)
      Overrides:
      equals in class Object
    • equalsBySdkFields

      public final boolean equalsBySdkFields(Object obj)
      Description copied from interface: SdkPojo
      Indicates whether some other object is "equal to" this one by SDK fields. An SDK field is a modeled, non-inherited field in an SdkPojo class, and is generated based on a service model.

      If an SdkPojo class does not have any inherited fields, equalsBySdkFields and equals are essentially the same.

      Specified by:
      equalsBySdkFields in interface SdkPojo
      Parameters:
      obj - the object to be compared with
      Returns:
      true if the other object equals to this object by sdk fields, false otherwise.
    • toString

      public final String toString()
      Returns a string representation of this object. This is useful for testing and debugging. Sensitive data will be redacted from this string using a placeholder value.
      Overrides:
      toString in class Object
    • getValueForField

      public final <T> Optional<T> getValueForField(String fieldName, Class<T> clazz)
    • sdkFields

      public final List<SdkField<?>> sdkFields()
      Specified by:
      sdkFields in interface SdkPojo
      Returns:
      List of SdkField in this POJO. May be empty list but should never be null.
    • sdkFieldNameToField

      public final Map<String,SdkField<?>> sdkFieldNameToField()
      Specified by:
      sdkFieldNameToField in interface SdkPojo
      Returns:
      The mapping between the field name and its corresponding field.